Skip to content
European CTEM platform

Your company, through an attacker's eyes.

blacklens.io finds exposed systems, exploitable vulnerabilities and leaked credentials and tells you what to fix first.

Try free for 14 days Book a demoBuilt and hosted in Europe
blacklens.io dashboard with issues, assets, services, dark web findings and exposure score

Visuals show sample data.

Used by manufacturers, retailers, software companies and IT service providers across the DACH region.

  • AMAG Austria Metall
  • TGW Logistics
  • Teufelberger
  • Condor
  • EVER Pharma
  • Baumit
  • E+E Elektronik
  • cafe+co
  • Hauser
  • Schauer Agrotronic
  • Holter
  • agru Kunststofftechnik

blacklens.io in numbers

Assets monitored
1M+
Vulnerabilities identified
100K+
Dark web leaks captured
50K+
Integrations for cloud, SIEM and ticketing
20+

How it works

How blacklens.io sees your company.

Four steps, one platform: find what is exposed, assess what matters, get early warnings and prove the fix.

  1. 01Discover

    blacklens.io finds external, internal and cloud assets automatically, including forgotten systems, shadow IT and lookalike domains.

    • External, internal and cloud
    • Shadow IT
    • Lookalike domains

    Explore Attack Surface Management

    Cloud accounts4 connected
    S3 bucket publicly accessibleAWSHigh
    Admin accounts without MFAMicrosoft 365Critical
    VM with public IPAzureMedium
    Public API endpointGoogle CloudMedium
  2. 02Assess

    EPSS, CISA KEV and exploit status show what really matters. AI explains every finding, running as a self-hosted LLM in Europe.

    • EPSS
    • CISA KEV
    • AI explanations

    Explore Vulnerability Management

    AI explanationself-hosted LLM
    CVE-2024-21762vpn.beispiel-gmbh.atKEVCritical
    Root cause
    Outdated FortiOS version on the SSL VPN gateway.
    Impact
    Attackers can execute code without logging in.
    Remediation
    Update to FortiOS 7.0.14 or later.
  3. 03Warn early

    New CVEs are matched against your inventory in real time. We also flag leaked identities and suppliers listed on leak sites.

    • Real-time CVE matching
    • Dark web identities
    • Supplier watchlist

    Explore early warning

    Supplier watchlist12 suppliers
    Logistik Partner GmbHListed on a ransomware leak site, 30 min agoCritical
    Software Zulieferer AGSoftwareNo hits
    Muster SteuerberatungTax advisoryNo hits
  4. 04Fix and prove

    One workflow for every finding: assign, fix, close automatically after the re-scan and prove progress with reports.

    • Jira, Teams, Slack
    • Auto-close after re-scan
    • Scheduled reports

    Explore Unified Vulnerability Management

    Remediationone workflow for every source
    12Open
    5In progress
    2Risk accepted
    48Closed
    CVE-2024-21762
    1. Assigned to IT operations
    2. Update installed
    3. Re-scan confirmed: closed automatically

Visuals show sample data.

Attackers see your company differently than your IT does.

blacklens.io shows the whole picture: external, internal, cloud and dark web, in one platform and prioritised by real risk.

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Attack Surface Management

Finds every domain, service and technology, including the forgotten ones.

Fix firstsorted by risk
1CVE-2024-21762vpn.beispiel-gmbh.atKEV
2CVE-2024-21410mail.beispiel-gmbh.atKEV
3TLS 1.0 enabledshop.beispiel-gmbh.atMedium

Vulnerability Management

200,000+ tests, prioritised by EPSS, CISA KEV and exploit status instead of CVSS alone.

Compromised identities3 new hits
m.hu•••@beispiel-gmbh.atStealer log, 2 h agoEmployee
Microsoft 365 session cookieStealer log, 5 h agoEmployee
k.wa•••@gmx.atCombolist, 3 days agoCustomer

Dark Web Monitoring

Leaked credentials and session cookies, before anyone uses them.

Sentry in the internal networkonline
Servers423 critical
Clients186
OT & IoT172 critical
Network91 critical
Active Directory12 accounts without sign-in for 90 daysMedium

Sentry: internal scanning

New

Servers, clients, OT and Active Directory behind the firewall.

Early warning47 min ago
CVE-2024-21762FortiOS SSL-VPNCritical
  1. CVE published08:12
  2. 2 assets in your inventory affected09:00
  3. Confirmed by PoC scan09:26
  4. Alert sent to Microsoft Teams09:27

Early warning

New CVEs matched in real time against your inventory and verified automatically.

Penetration testmanually validated
Authentication can be bypassedportal.beispiel-gmbh.atVerified
Other users' records readable via APIapi.beispiel-gmbh.atRetest passed
No limit on login attemptsshop.beispiel-gmbh.atUnder review

Penetration Testing

Pentesters validate findings manually, with retest and report inside the platform.

Integrationsalerts, tickets, cloud
  • Jira
  • Microsoft Teams
  • Slack
  • GitHub
  • GitLab
  • Elastic
  • AWS
  • Microsoft Azure
  • Google Cloud
  • Cloudflare
  • Hetzner
  • Webhook
REST API250+ endpoints

Integrations

Alerts in Jira, Teams, Slack, Sentinel or Elastic. Everything via REST API too.

Visuals show sample data.

Platform

One platform. From source to remediation.

Every source feeds one analysis that prioritises by real risk. The result: tasks, reports and alerts in the tools you already use.

  1. 01

    Sources

    What attackers can see: from outside, in the internal network, in the cloud and on the dark web.

  2. 02

    Analysis

    Prioritised by exploitability, explained in plain language and verified.

  3. 03

    Action

    Assigned, documented and where your team already works.

Dark Web Monitoring

What the dark web knows about your company.

Access brokers sell entry points before ransomware groups strike. blacklens.io finds compromised accounts, infected devices and stolen session cookies and turns them into findings.

  • Employee or customerHits are classified automatically by your domains.
  • Ransomware leak sitesVictim lists matched about every 30 minutes, including your suppliers.
  • Session cookiesStolen Microsoft 365 and VPN sessions are detected and assessed.
Dark web monitoring in blacklens.io: compromised devices with details of the infected device
Compromised identityEmployee

m.hu•••@beispiel-gmbh.at

Stealer log, 2 h ago

Visuals show sample data.

Data sovereignty

Made in Europe is not a marketing line for us.

Platform, scanners and AI run on European infrastructure, built and operated by an Austrian company.

About us
  • DACH hosting

    ISO 27001 and SOC 2 certified data centres, scanners only in Austria, Germany and Switzerland.

  • Self-hosted LLM/AI

    No external AI providers, consent per workspace.

  • Austrian vendor

    snapSEC GmbH in Vorchdorf, German-speaking support.

  • One licence, every module

    Priced by assets and users, reports, API and integrations included.

Security that companies trust.

Experiences from manufacturing, retail, software and IT services.

“blacklens.io is the ideal complement to our internal IT security measures. It continuously checks our externally reachable systems, tells us when action is needed and is an important building block of our cyber defence.”
Christian Mondl, Smarter Ecommerce GmbH

Latest analysis

Get started

See your attack surface within 24 hours.

We set up your workspace and walk you through the first findings.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings

Three steps to your first priority

  1. 1 Start

    Connect domains and cloud

  2. 2 Within hours

    First scan runs automatically

  3. 3 Within 24 hours

    Prioritise and fix

blacklens.io dashboard with issues, assets, exposure score and alerts